Arbitrary Code Execution Vulnerability in Autodesk Applications
CVE-2025-5039

7.8HIGH

Key Information:

Vendor

Autodesk

Status
Vendor
CVE Published:
24 July 2025

What is CVE-2025-5039?

An arbitrary code execution vulnerability exists in certain Autodesk applications due to a maliciously crafted binary file that can be loaded during file operations. This flaw stems from an untrusted search path, enabling attackers to execute unauthorized code within the affected process. Users are advised to follow security advisories and implement measures to mitigate risks.

Affected Version(s)

RealDWG 2026 < 2026.0.2

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-5039 : Arbitrary Code Execution Vulnerability in Autodesk Applications